scuttle/CHANGELOG.md

7.3 KiB
Executable File
Raw Permalink Blame History

scuttle — Changelog

v0.4.0 — Verification + Audit Exporters + Signing + Firmware Erase (2026-08-04)

Fourth tagged release. Combines the v0.5 (Verification and Audit) and v0.6 (Firmware Erase) milestones from docs/MANIFEST.md §15.

Added

v0.5 Layer 6 — Extended Verification (scuttle-verify)

  • Spot verification (verify_static_pattern_spot): reads N% of blocks at pseudorandom offsets and compares against the expected pattern. Default 5%.
  • Block verification (verify_static_pattern_blocks): reads fixed-size blocks (e.g. 1 MiB) for large devices where sector-by-sector is too slow.
  • Statistical verification (compute_statistics, verify_statistical):
    • Shannon entropy (bits per byte, 0.08.0).
    • Chi-square statistic for uniform distribution (256 buckets).
    • Chi-square p-value (Wilson-Hilferty approximation, 255 degrees of freedom).
    • Byte frequency max deviation.
  • Failure mapping (FailedRange): tracks LBA start/end + expected/actual hex for each mismatch.
  • VerifyResult now carries failed_ranges: Vec<FailedRange> and stats: Option<StatisticalResult>.
  • 5 new unit tests (statistics on zeros, statistics on random, spot verify pass, spot verify mismatch, block verify).

v0.5 Layer 7 — Audit Exporters + Merkle Tree (scuttle-audit)

  • XML exporter (to_xml): well-formed XML with sorted keys, CDATA-escaped text.
  • CSV exporter (to_csv): single-row flat format with all key fields.
  • HTML exporter (to_html): self-contained HTML page with embedded CSS, styled result (green/red), and a <pre> block with the full JSON.
  • YAML exporter (to_yaml): via serde_yaml.
  • Merkle tree (MerkleTree): builds a SHA-256 Merkle tree over per-block hashes of the wiped device. Supports from_leaves and from_data. Pads to power-of-two.
  • NIST SP 800-88 compliance report (ComplianceReport): maps the audit record's NIST class (Clear/Purge/Destroy) to compliance evidence. Serializable to JSON.
  • VerifyResultJson now carries stats: Option<StatisticalResultJson>.
  • 9 new unit tests (Merkle single/two/three/from_data, XML/CSV/HTML/YAML export, compliance report).

v0.5 Layer 7 — Signing (scuttle-signing)

  • scuttle-signing crate: Ed25519 digital signatures for audit records.
    • sign_ed25519(record, key)SignatureResult (algorithm, signature_hex, key_fingerprint, signed_payload_hash).
    • verify_ed25519_with_key(record, sig, public_key)bool.
    • load_ed25519_key(path) — load a 32-byte seed from file.
    • generate_ed25519_keypair() — for testing.
    • key_fingerprint(public_key) — SHA-256 of the public key, hex-encoded.
    • SignerBackend trait + Ed25519Signer, OpenPgpSigner (stub), X509Signer (stub).
    • SignatureJson for embedding in the audit record.
  • 8 unit tests (sign+verify roundtrip, wrong-key failure, signature changes with record, OpenPGP/X.509 stubs return NotImplemented, signer backend trait, key load rejects wrong length, key load 32 bytes).

v0.6 Layer 9 — Firmware Erase (scuttle-firmware)

  • scuttle-firmware crate: firmware-level sanitization commands.
    • ATA Secure Erase (ata_secure_erase, ata_secure_erase_enhanced): via hdparm --security-erase / --security-erase-enhanced. Includes ata_detect_secure_erase and ata_set_security_password.
    • NVMe Sanitize (nvme_sanitize): supports Block Erase, Crypto Erase, Overwrite actions via nvme-cli. Includes nvme_sanitize_status polling (up to 1 hour timeout).
    • NVMe Format NVM (nvme_format): format namespace with block size + secure erase setting (None / UserDataErase / CryptographicErase).
    • SCSI Sanitize (scsi_sanitize): via sg_sanitize --overwrite.
    • SCSI Format Unit (scsi_format): via sg_format --format --six.
    • TRIM (trim_discard): direct ioctl(BLKDISCARD) over the entire device.
    • FITRIM (fitrim): direct ioctl(FITRIM) on a mounted filesystem.
    • HPA/DCO detect + disable (detect_hpa_dco, disable_hpa, disable_dco): via hdparm -N and hdparm --dco-identify / --dco-restore.
    • High-level dispatch (run_firmware_erase): takes a PurgeMethod + device path, runs the right command, returns FirmwareResult.
  • Tools are detected at runtime; if absent, returns FirmwareError::ToolNotFound.
  • 8 unit tests (which() finds known binaries, HPA/DCO parse helpers, ATA detect returns gracefully without hdparm).

v0.6 Policy engine integration (scuttle-policy)

  • WipePlan now carries firmware_erase: Option<PurgeMethod>.
  • SSD policies set firmware_erase = AtaSecureErase (or AtaSecureEraseEnhanced if supported) for Purge/Enterprise/Forensic/Government/AirGap/Paranoid intents.
  • NVMe policies set firmware_erase = NvmeSanitizeCrypto for the same intents.
  • PMEM policy sets firmware_erase = PmemCryptoErase (returns Unsupported at runtime since ndctl integration is deferred to v0.7).
  • HDD / virtual / freespace policies leave firmware_erase = None.
  • 5 new tests verify the firmware_erase field is set correctly.

v0.6 Core wipe engine integration (scuttle-core)

  • JobOptions now carries firmware_erase: Option<PurgeMethod>.
  • The wipe engine invokes scuttle_firmware::run_firmware_erase BEFORE the overwrite passes.
  • Firmware erase failures are logged and recorded in audit.notes but do NOT abort the wipe — the overwrite passes still run as belt-and-braces.

CLI integration

  • --certificate now accepts: none, json, pdf, xml, csv, html, yaml, both (json+pdf), all (all 6 formats).
  • CLI overrides for --rounds, --verify, --certificate, --noblank are now correctly re-applied after the policy engine runs (previously the policy engine's profile defaults would overwrite CLI overrides).

Tests

  • 105 tests total (was 70 in v0.3):
    • 5 new in scuttle-verify (spot/block/statistical).
    • 9 new in scuttle-audit (exporters + Merkle + compliance).
    • 8 new in scuttle-signing (Ed25519 sign/verify + stubs).
    • 8 new in scuttle-firmware (parse helpers + which).
    • 5 new in scuttle-policy (firmware_erase field).

Known limitations

  • Firmware erase requires hdparm, nvme-cli, and sg3_utils to be installed. If absent, the function returns ToolNotFound and the wipe continues with overwrite-only.
  • PMEM crypto-erase requires ndctl (deferred to v0.7).
  • OpenPGP and X.509 signing are stubs (deferred to v2.0).
  • The Merkle tree is built but not yet signed or bound into the audit record (the signing happens over the canonical JSON, not the Merkle root — full Merkle-root signing arrives in v0.7).

v0.3.0 — Modern Providers + Profiles/Policies + Freespace Mode (2026-08-04)

See git history for full v0.3.0 changelog. Summary: 5 modern PRNGs (BLAKE3-XOF, XChaCha20, SHAKE128, SHAKE256, Salsa20); Layer 16 benchmark framework; v0.4 modern profile TOML schema with policy_map + constraints; policy engine with 20 built-in policies; 11 modern profiles; --freespace-only mode; fixed MT19937 + ISAAC-64 KAT bugs.


v0.2.0 — Legacy Compatibility (2026-08-04)

See git history. Summary: legacy profiles, legacy flag compatibility, PDF certificate exporter, nwipe symlink support.


v0.1.0 — Architectural Bootstrap (2026-08-04)

See git history. Summary: Layers 1-7 + 13 implemented from scratch in Rust; 24 tests passing.